Password Myths That Weaken Security
Some popular password advice actually makes accounts weaker. Eight common password myths, what current guidance from NIST and the UK's NCSC says instead, and what to do.

Password advice has changed a lot in the past decade, but old rules live on in office policies and well-meaning tips. Some of them actively make passwords weaker. Here are the most common myths and what current guidance says instead.
Myth 1: A strong password needs symbols, numbers and capitals
Reality: length matters more. Forced complexity leads to predictable patterns like Password1!, which cracking tools try first. A long passphrase of random words is stronger and easier to remember. See how long a password should be.
Myth 2: You should change passwords every few months
Reality: NIST guidance says systems should not force regular changes without a reason. Frequent forced changes lead to small, predictable tweaks (Lantern1, Lantern2). Change a password when there is a reason: a breach, a leak warning or suspicious activity.
Myth 3: One really strong password is enough for everything
Reality: strength does not help when a site is breached and the password leaks. Uniqueness matters as much as strength. See why password reuse is so dangerous.
Myth 4: Password managers put all your eggs in one basket
Reality: a reputable password manager with a strong main password and two-step verification is far safer than reusing passwords or keeping them in a notes app. See how to set up a password manager.
Myth 5: Never write a password down
Reality: a few important passphrases written on paper and kept safely at home are a reasonable backup, and less risky than reusing passwords. The risk is mostly from people who can access your home, not criminals online. Do not stick them on your screen, and do not store them unprotected on your phone.
Myth 6: Security answers should be true
Reality: honest answers are often findable online. Random answers stored in a password manager are safer. See security questions.
Myth 7: A strong password means you do not need two-step verification
Reality: passwords can be phished or leaked however strong they are. Two-step verification stops most attacks that use a stolen password. See what two-step verification is.
Myth 8: Hackers are not interested in my accounts
Reality: most attacks are automated and aimed at everyone. Your email, social media and payment accounts are valuable for scamming your contacts, making purchases and resetting other accounts.
The modern formula: long, unique passwords, stored in a password manager, with two-step verification on important accounts.
Received a "password expiring" email? Paste it into CyberWatch AI Scan for a free check. Fake expiry notices are a common phishing trick.
For the full picture, read our complete guide to identity theft and account security.
Frequently asked questions
Should I change my passwords every 90 days?
Current guidance says not without a reason. Change a password when there is evidence it may be compromised, such as a breach or suspicious activity.
Is writing passwords down always bad?
Writing a few important passphrases on paper kept securely at home is less risky than reusing one password everywhere. A password manager is better still.
Are long passwords with no symbols weak?
No. Length adds more strength than symbols. A long passphrase of random words is strong even without special characters.
Sources
- NIST SP 800-63B: Authentication and Lifecycle Management, US National Institute of Standards and Technology
- Three random words, UK National Cyber Security Centre
- Creating Strong Passwords and Other Ways To Protect Your Accounts, US Federal Trade Commission


